Skip to content

ci: gate the release genesis key behind the releases environment - #316

Merged
re-gius merged 2 commits into
masterfrom
chore/gate-release-secrets
Sep 23, 2026
Merged

re-gius merged 2 commits into
masterfrom
chore/gate-release-secrets

Conversation

@re-gius

@re-gius re-gius commented Sep 22, 2026 •

Copy link
Copy Markdown
Collaborator

Description

The genesis owner key DOTNS_ADMIN_KEY was a repository-level secret, readable by any workflow on any branch, with a silent mnemonic fallback deciding the owner when unset.

  • Both publish jobs now run in the releases environment: reviewer approval required, refs limited to master and v[0-9]* tags, key stored as an environment secret.
  • A pre-build step checks the key derives to the environment's declared DOTNS_ADMIN_ADDRESS, so a mistyped key fails before a genesis is built.
  • The mnemonic fallback is removed from the genesis script: one explicit key, or a loud failure.

Follow-up once merged: delete the repository-level DOTNS_ADMIN_KEY and DOTNS_ADMIN_MNEMONIC, whose last consumers this PR removes.

Type

  • Bug fix
  • Feature
  • Breaking change
  • Documentation
  • Chore
  • Refactor
  • Security

Scope

  • Registration
  • Resolver
  • Store
  • Proof of Personhood
  • Deployment scripts
  • Tests

Related Issues

Fixes

Checklist

Code

  • Follows project style
  • forge build passes
  • forge test passes
  • No new compiler warnings

Testing

  • New tests added for changed behavior
  • Fuzz tests added where applicable
  • Invariant tests verified

Security

  • No new selfdestruct or delegatecall
  • Access control reviewed
  • No storage layout conflicts (for upgradeable contracts)

Documentation

  • NatSpec updated on changed interfaces
  • README updated if needed

Breaking Changes

  • No breaking changes
  • Breaking changes documented below

Breaking changes: a release run now requires the releases environment to exist with DOTNS_ADMIN_KEY and DOTNS_ADMIN_ADDRESS configured, and pauses for a reviewer approval. Building a genesis locally with only DOTNS_ADMIN_MNEMONIC set no longer works; pass DOTNS_ADMIN_KEY.
workflow_dispatch releases can only be started from master; a dispatch from another branch stops at the environment gate.

How to test

bash -n scripts/genesis/build-genesis.sh

# refuses without a key, with a message naming the one accepted credential
unset DOTNS_ADMIN_KEY DOTNS_ADMIN_MNEMONIC; bash scripts/genesis/build-genesis.sh release

The full gate is exercised by the next prerelease: the run must pause on the releases environment, pass the address check, and build with the fresh key.

Notes

The environment itself (reviewers, ref patterns, secret, variable) has already been configured.

@re-gius
re-gius requested a review from a team as a code owner September 22, 2026 09:49
@github-actions

github-actions Bot commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

CI Summary

Check Result
File Validation Passed - All tracked files valid
Deploy Contracts Reproduces the expected address set; resume verified
PR Title PR Title Valid
Labels Unknown
Secret Scan Passed - No secrets detected

Deploy Contracts

Deployed addresses vs the expected set

Expected is the committed expected-address set; actual is this CI deployment of the same pipeline.

Contract Expected Actual Match
Create3Factory 0x8533c79E058c5a6489CAFeCA86dc600E029D75f5 0x8533c79E058c5a6489CAFeCA86dc600E029D75f5 match
DotnsContentResolver 0x7F74D7CD50f5a834270E2ad395a01b01891AB37d 0x7F74D7CD50f5a834270E2ad395a01b01891AB37d match
DotnsCostModelRegistry 0x8bfd1f0957e73716732e725802f13830B5682da4 0x8bfd1f0957e73716732e725802f13830B5682da4 match
DotnsFlatPricing 0xD839B281dF72Df44fF275305E72cAEEc0fDAA648 0xD839B281dF72Df44fF275305E72cAEEc0fDAA648 match
DotnsNameEscrow 0x4881Afb78e7C908cAe818168B926229D93376520 0x4881Afb78e7C908cAe818168B926229D93376520 match
DotnsNameWhitelist 0x420166cD67Ca0233094E492a4BbA67045eD7C38C 0x420166cD67Ca0233094E492a4BbA67045eD7C38C match
DotnsPopController 0xCC932348606cc1f3318cADeC5A5Cd2CA447f8a4b 0xCC932348606cc1f3318cADeC5A5Cd2CA447f8a4b match
DotnsPopLens 0xfe5A45f7fD58D1A6FE09455DB799405b1dcE9411 0xfe5A45f7fD58D1A6FE09455DB799405b1dcE9411 match
DotnsPopResolver 0xDaC984884EcA8Fc44011f1D6C49B27828390A72B 0xDaC984884EcA8Fc44011f1D6C49B27828390A72B match
DotnsProtocolRegistry 0xD19e3D0C97CF501125a04A97405e3e6592fa846E 0xD19e3D0C97CF501125a04A97405e3e6592fa846E match
DotnsRegistrar 0x4f06E818Ba3d987704fd91cf3d868E4b019106Ab 0x4f06E818Ba3d987704fd91cf3d868E4b019106Ab match
DotnsRegistrarController 0xBdaA01bD1bA67d709F2b1fF286Da0d854977EA30 0xBdaA01bD1bA67d709F2b1fF286Da0d854977EA30 match
DotnsRegistry 0xf34054fd76BbF85f216cf9908226D5f0A72E50CA 0xf34054fd76BbF85f216cf9908226D5f0A72E50CA match
DotnsResolver 0xbd1165E549DF96F083c0A16f61590927bC187009 0xbd1165E549DF96F083c0A16f61590927bC187009 match
DotnsReverseResolver 0xee3883d7eB60Ee9BCD7F3bcD8f2f05302A9Cc035 0xee3883d7eB60Ee9BCD7F3bcD8f2f05302A9Cc035 match
LabelStoreBeacon 0x2227d9807F5A71332Aaa0640643030f2A3bf84cD 0x2227d9807F5A71332Aaa0640643030f2A3bf84cD match
Multicall3 0xB4468000abD87D3c56cbFBd153161223D7b109e5 0xB4468000abD87D3c56cbFBd153161223D7b109e5 match
PopRules 0x747B456bE03aec0b42bd85C51513730FBD45DA31 0x747B456bE03aec0b42bd85C51513730FBD45DA31 match
StoreFactory 0x99605a926FcB40aB520F659c6505E5ff862771f6 0x99605a926FcB40aB520F659c6505E5ff862771f6 match
UserStoreBeacon 0x3d1Ca165f7A5e387C2df02DB2FadD3149c1C72ad 0x3d1Ca165f7A5e387C2df02DB2FadD3149c1C72ad match

View full logs

Labels

other, type: docs

@github-actions github-actions Bot added the other label Sep 22, 2026
@GHkrishna

Copy link
Copy Markdown
Contributor

Overall looks good, just a few nits:

A short section in RELEASE_ARTIFACTS.md would be good regarding the environment name, the two entries and which is a secret vs a variable, the required reviewers, the ref patterns, and the note that a v* tag ruleset should sit beside it since a tag push reaches the same job on Contents: write.

Rn the orger is checkout, setup-foundry, setup-bun, setup-node, build contracts, run tests, then this check. Can we add the check right after setup-foundry, this was any incorrect key gives error way before we execute the other intense ops.

@GHkrishna

Copy link
Copy Markdown
Contributor

One question:

The deployment branch policy allows master and v[0-9]*. Both workflows also accept workflow_dispatch, where the tag is created from whichever branch the run was started on. That means a dispatch from any branch other than master will now fail at the environment gate rather than at the build. Do we want to add that as a breaking change maybe, I'm not 100% sure of it though

Comment thread .github/workflows/publish-prerelease.yml
Comment thread .github/workflows/publish-release.yml
@re-gius

re-gius commented Sep 22, 2026

Copy link
Copy Markdown
Collaborator Author

A short section in RELEASE_ARTIFACTS.md would be good regarding the environment name, the two entries and which is a secret vs a variable, the required reviewers, the ref patterns, and the note that a v* tag ruleset should sit beside it since a tag push reaches the same job on Contents: write.

Rn the orger is checkout, setup-foundry, setup-bun, setup-node, build contracts, run tests, then this check. Can we add the check right after setup-foundry, this was any incorrect key gives error way before we execute the other intense ops.

Both taken in e0d1244 , the check now runs after the foundry step and the publishing section of RELEASE_ARTIFACTS.md now documents the environment.

@re-gius

re-gius commented Sep 22, 2026

Copy link
Copy Markdown
Collaborator Author

One question:

The deployment branch policy allows master and v[0-9]*. Both workflows also accept workflow_dispatch, where the tag is created from whichever branch the run was started on. That means a dispatch from any branch other than master will now fail at the environment gate rather than at the build. Do we want to add that as a breaking change maybe, I'm not 100% sure of it though

Confirmed, and it's intended: releases should only cut from master, so a dispatch from another branch stopping at the environment gate is the desired outcome. Added it to the PR's breaking changes.

Also added a new tag ruleset to restrict permissions for creating v* tags to dotns team and repo admins.

@re-gius
re-gius merged commit 408f75e into master Sep 23, 2026
11 checks passed
@re-gius
re-gius deleted the chore/gate-release-secrets branch September 23, 2026 06:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants